IT Business Management Associate Director
Are you ready to make an impact at DTCC? Work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development. At DTCC, we are at the forefront of innovation in the financial markets and are committed to helping our employees grow and succeed.
About the Role
Within the Cybersecurity Business Office, this role serves as a trusted advisor to the business, shaping and guiding cyber risk–informed decision-making across the enterprise. You will ensure security investments are aligned to the threat landscape and risk appetite, effectively funded, and focused on delivering measurable risk reduction, strengthening resilience, protecting critical assets, and enabling sustainable, secure business growth.
Responsibilities
- Define and drive the enterprise Cybersecurity strategy aligned to business objectives, regulatory requirements, and evolving threat landscape.
- Translate cybersecurity risk insights (threat intelligence, assessment results, and issues/control gaps) and strategic priorities into a structured, multi-year cybersecurity roadmap in alignment with Business, IT, and Cybersecurity objectives.
- Understand and contextualize how the achievement of Cybersecurity strategic objectives will continue to mature the Cybersecurity program against the core Cyber Risk Institute Profile (CRI Profile) principles and tenets.
- Develop and manage a portfolio of cybersecurity initiatives spanning vulnerability management, threat intelligence and detection, identity access management, data protection, as well as cybersecurity architecture and resilience.
- Structure the cybersecurity roadmap into programs and projects mapped to key risk domains and control frameworks (e.g., CRI Profile).
- Prioritize initiatives based on alignment to strategic objectives, risk reduction, business impact, and regulatory exposure.
- For each identified cybersecurity initiative, assist in the definition of milestones and success criteria tied to tangible security outcomes (e.g., reduced attack surface, improved patching, expanded Role-Based Access).
- Oversee the execution against milestones with a focus on risk reduction progress, not just delivery completion.
- Assist in developing and presenting executive reporting on cyber posture improvement, emerging risks, and program effectiveness.
- Design and manage the cybersecurity program budget, including:
- Operational security capabilities (SOC, vulnerability management, IAM)
- Capital investments in security tooling and infrastructure
- Specialized cyber professional services (incident response, advisory, assessments)
- Monitor and forecast cybersecurity spending against budget, ensuring efficient allocation of resources across risk domains.
- Evaluate cost vs. risk reduction value for tools, services, and programs to optimize investment decisions.
- Lead the development of bi-monthly cybersecurity board reporting, translating complex cyber risks, threats, and control performance into clear, executive-level insights.
- Synthesize inputs across vulnerability management, IAM, threat intelligence, incident response, and control effectiveness into concise, decision-oriented updates.
- Provide a risk-informed narrative on the organization’s cyber posture, highlighting emerging threats and critical issues (including high-risk vulnerabilities, control gaps, and delayed remediations, with recommended actions).
- Analyze interdependencies across Cybersecurity projects, including financial benefits, resource constraints, risk mitigation, client satisfaction, and strategic alignment.
- Partner closely with Cybersecurity senior leadership and Finance management to drive informed decision-making.
Requirements
- Minimum of 8 years of related experience.
- Bachelor's degree preferred or equivalent experience.
Skills
- Management consulting experience preferred, with the ability to assess complex cybersecurity challenges, provide structured recommendations, and effectively communicate solutions to leadership.
- Ability to create effective working relationships with senior business, cybersecurity, technology, and risk/control leadership.
- Ability to synthesize large amounts of information inclusive of project progress, risks, and issues into board-ready deliverables illustrating critical information to drive risk-based decisions.
- Strong cybersecurity acumen with technical expertise across Identity Access Management, Vulnerability and Threat Intelligence, and Data Protection capabilities.
- Effective collaboration, expectations management, and partnership with multiple internal and external stakeholders.
- Strong critical thinking skills with the ability to identify interdependencies across cybersecurity processes, tools, and stakeholders to proactively mitigate risks and drive effective decision-making.
- Experience translating multiple data elements (both financial and cyber-oriented) into tangible products that drive insights and decision-making.
- Experience with cybersecurity strategy development and portfolio governance.
- Knowledge of Cybersecurity Financial Management, specifically related to operational, capital, and professional service expenses.
Pay and Benefits
- Competitive compensation, including base pay and annual incentive.
- Comprehensive health and life insurance and well-being benefits, based on location.
- Pension/Retirement benefits.
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Schedule
DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays, and a third day unique to each team or employee).